Resources · 118

TLS renewal: verify the certificate actually being served

Follow renewal through every termination point and supported client before declaring the change complete.

· 2 min

Server racks in a data centre Illustration · fictional scene

What this guide helps achieve

  • Inventory TLS termination points
  • Prepare issuance, distribution and reload
  • Verify through clients and monitor

Quick check

  • Termination map and observed expiries.
  • Verified renewal and distribution procedure.
  • Client evidence, alerts and change completion criteria.

Step-by-step method

  1. 01

    Inventory TLS termination points

    List expected names, CDNs, load balancers, proxies and internal connections presenting certificates. Record actual served certificate, chain, expiry and owner at each relevant point. Successful issuance does not establish installation on every node. Protect private keys and exclude them from the register.

    Termination map and observed expiries.

  2. 02

    Prepare issuance, distribution and reload

    Test automation against provider staging where available. Check validation challenges, SAN name coverage, protected storage and component reload. Avoid issuance on every instance startup when a usable certificate exists under your key policy.

    Verified renewal and distribution procedure.

  3. 03

    Verify through clients and monitor

    Check names, validity dates and trust chain with supported clients over relevant paths. Keep TLS verification enabled. Monitor the served certificate’s expiry, not just scheduler status. Rollback requires a still-valid certificate and uncompromised key; otherwise fix or isolate the failing point.

    Client evidence, alerts and change completion criteria.

Acceptance case to reproduce

Fictional example: these inputs describe no customer or observed result.

View case inputs
{
    "issuance_succeeded": true,
    "proxy_count": 2,
    "proxies_serving_expected_certificate": 1,
    "other_proxy_certificate_expired": true,
    "tls_verification_enabled": true,
    "expected": "change_incomplete_fix_and_verify_client_paths"
}

Expected decision

Fictional example: renewal succeeds, but one of two proxies still serves an expired certificate. The change remains incomplete: fix that proxy and check client paths instead of disabling TLS validation.

Let’s Encrypt — Integration Guide

Your acceptance workbook

Record observations against this guide’s criteria. A record is not certification.

The workbook does not save automatically. Export before leaving.

Management indicators

IndicatorWhat it measuresFirst action
Verified current terminationsChecked points serving expected certificates / inventoried pointsDisclose unobservable points
Minimum observed time to expiryShortest remaining validity among checked served certificatesState observation time and coverage

Common pitfalls

    Frequently asked questions

    Is successful ACME renewal enough to close the change?

    No. Verify distribution, reload and the certificate actually presented to clients. One node may still serve an older certificate.

    Official references

    References consulted: . The method and worksheet propose checks to adapt to your context; they do not constitute certification.